Skip to content

Roadmap: context-aware shortcuts, system automation, and release trust #431

Description

@zjlgdx

Goal

Track the scoped work selected after a read-only comparison of Wink and Thaw. This issue is the dependency and product-boundary source of truth; each implementation remains one issue, one branch, one PR, and one verification loop.

Verified baseline

  • Wink baseline: main@a7672dce.
  • The repository had no open issues when this roadmap was created.
  • Existing wink://toggle, wink://pause, and wink://resume were delivered by Automation interface: wink:// URL scheme and CLI for toggle semantics #355; recipes/import-export were delivered separately and are not Profiles.
  • Thaw is GPL-3.0. It is a behavioral reference only; no Thaw source, assets, tests, corpus, or workflow may be copied into Wink.

Delivery queue

Independent product work

Strategic Profiles line

Release and supply-chain trust

Bounded research

Dependency graph

#436 Profiles design -> #437 Profiles implementation -> #438 Focus Filter

#439 Actions SHA lifecycle -> #441 OSV
                            -> #442 CodeQL (if advanced workflow)
                            -> #443 artifact attestations

#440 Developer ID/notarization ---------> #443 production release proof

Governing principles

  • Keep ordinary App Intents separate from Focus Filters.
  • Treat Shortcut Profiles as the strategic product line, but ship smaller independent improvements first.
  • Preserve Wink's macOS 15 deployment target and current permission boundary; do not add Screen Recording.
  • Use idempotent automation actions where possible. Never report an asynchronous activation/hide request as completed before Wink observes its final outcome.
  • Runtime-sensitive work must carry exact-head packaged-app evidence under the repository's macOS validation policy.
  • Supply-chain provenance, Developer ID/notarization, TCC designated requirements, and Sparkle signatures are separate trust mechanisms and must not be conflated.
  • A green check with zero discovered packages, zero analyzed Swift files, or an unavailable suite is not positive verification.

Explicitly deferred

  • A true-success x-callback protocol for activation/hide outcomes.
  • Broad defaults write overrides for cooldown, debounce, F19, or other safety timings.
  • Crowdin, Settings Search, arbitrary Profile scripts/hooks, and settings read/write URLs.
  • Homebrew distribution until Require Developer ID signing and notarization for public releases #440 is operationally proven; Homebrew remains a separate ecosystem/release decision.

Completion

This roadmap closes only when every non-deferred child issue is either completed or explicitly re-scoped with a documented decision. Closing one child issue does not complete the roadmap.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions